Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://hackerone.com/reports/642515 | third party advisory exploit |
https://nextcloud.com/security/advisory/?id=NC-SA-2020-017 | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KC6HLX5SG4PZO6Y54D2LFJ4ATG76BKOP/ | vendor advisory |